Book a demo →
← All insights AI News

One Vendor Promises Provenance, Another Ships It, and the Foundation Cracks

One Vendor Promises Provenance, Another Ships It, and the Foundation Cracks

Three things happened to content provenance this month, and they only make sense together.

A vendor promised it. A different vendor turned out to be shipping it already. And a researcher showed that the signature scheme underneath does not hold on a whole class of devices.

The promise

On 11 August, Anthropic said it would embed watermarks in the text and files generated by future models it launches in the EU, as part of complying with the AI Act’s content and transparency rules.

The wording from the company’s help document: “Generated text will carry embedded watermarks, and generated files will include digitally signed provenance metadata where supported.”

Two qualifications belong next to that, and both are in the same report. It covers future models, with work under way on already-released ones during the transition period EU law allows. And it is framed around models launched in the EU, not as a global product change.

This is an announcement of intent with a compliance deadline behind it. It is not a description of what the product does today.

The delivery

While that was being announced, something similar was already running on hundreds of millions of Windows machines, without a press release.

A teardown published on 20 August found that MS Paint and Photos embed an identifier into the pixels of AI-generated images, including images generated locally on the device’s NPU.

The finding that makes this more than a checkbox: “The server’s watermarkId, the identifier embedded into the pixels, and the C2PA c2pa.soft-binding.value are the same per-generation value.”

Per generation. Each image carries its own value, tied to a server-side record, which is a far more specific object than a flag saying “this is AI”. Only one of the two can be used to look up who made a given picture and when.

The crack

On 25 August, a researcher published a way to defeat C2PA on Android devices with root access.

The mechanism is not a broken cipher. The phone’s StrongBox will sign arbitrary data on request, without the attacker ever learning the keys, and the attestation mechanisms meant to detect a compromised device do not reliably do so. Affected hardware includes Pixel 8a and 9a and Samsung devices. The routes in include CVE-2026-43499, a one-click root, and electromagnetic fault injection, which is hardware-level and not patchable. The tooling has a name: keystork.

Google’s response is the part that deserves quoting. The report was closed as “Won’t fix (infeasible)” — and Google paid a $7500 bounty anyway, while noting that hardware glitching and side-channel attacks are out of scope for the programme.

The researcher’s own reasoning for why it will not be fixed is more damning than the bug: repairing C2PA on Android would mean rearchitecting the whole image pipeline, and even then, in their words, “you still can’t stop ‘picture of screen’ style attacks.”

That sentence is the floor under this entire field. A camera pointed at a screen produces a genuinely signed photograph of a fake image. The signature is valid and the content is a lie.

What is not established

The Android break does not touch Anthropic’s text watermarks or Paint’s pixel identifier. It concerns C2PA signatures produced by Android camera hardware. The connection between these three stories is thematic, not technical, and treating them as one broken system would be wrong.

Anyone writing “AI watermarking is broken” on the strength of this has merged three separate mechanisms into one claim that none of the three sources makes.

What it does mean

Provenance systems answer a narrow question well and a broad question badly.

The narrow question is did this file come out of this pipeline, and a per-generation identifier answers it precisely. That is genuinely useful, and Paint’s implementation shows it can ship quietly at scale.

The broad question is is this image true, and no signature scheme answers it. A signed photograph of a screen, a signed render of a staged scene, a signed image with an honest chain of custody and a dishonest subject — all of these pass.

The combination to watch is the one that emerged this month by accident: a vendor announcing provenance for regulatory reasons, a vendor shipping it without announcing it, and a signature layer that a determined party can forge on common hardware. All three are true at once.

What to do with it

If provenance metadata is part of a workflow you rely on, find out which layer you actually depend on. Trusting a per-generation identifier from a specific vendor’s pipeline is a different bet from trusting a camera’s C2PA signature.

If you publish, assume that the presence of provenance data will be read as proof of authenticity by people who have not read any of this. That gap is now a communications problem as much as a technical one.

And if you are waiting for watermarking to settle the question of what is real, the researcher who broke it has already told you it will not, and Google agreed by declining to fix it.

Sources

  • The Register, “Anthropic pledges to embed watermarks to help discern AI slop in sop to EU”, 11 August 2026: https://www.theregister.com/ai-and-ml/2026/08/11/anthropic-pledges-to-embed-watermarks-to-help-discern-ai-slop-in-sop-to-eu/5285792 (retrieved 27 August 2026). Source of the pledge, its scope for future models launched in the EU, the quoted help-document wording, and the transition-period work on already-released models.
  • Xusheng, “MS Paint invisible watermark”, article dated 20 August 2026: https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/ (retrieved 27 August 2026). Source of the pixel-embedded identifier, its presence with local NPU generation, and the quoted finding that the server watermarkId, the embedded identifier and the C2PA soft-binding value are the same per-generation value.
  • David Buchanan, “Android C2PA”, article dated 25 August 2026: https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html (retrieved 27 August 2026). Source of the StrongBox signing mechanism, the unreliability of attestation on compromised devices, the affected hardware, CVE-2026-43499, the electromagnetic fault-injection route, the keystork tooling, the “Won’t fix (infeasible)” resolution, the $7500 bounty and Google’s out-of-scope note, and the quoted point about “picture of screen” attacks.
  • All quotations in this article were verified against the page sources rather than against summaries.

Try Truffle
free

7-day trial with the full feature set. No credit card.

Start tracking →

Newcomer AI-Visibility Tracker · known from